CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vertiv 1Avocent Umg 4000 Firmware Nov 21, 2024 Mar 30, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected XSS in an HTTP POST parameter. The web application does not neutralize user-controllable input before displaying to users in a...Show more |
The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to stored XSS. A remote attacker authenticated with an administrator account could store a maliciously named file within the web application...Show more |
1Vertiv 1Avocent Umg 4000 Firmware Nov 21, 2024 Mar 30, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes code syntax before executing. Since all commands within the web applica...Show more |